Living Off Trusted Sites: Zoom service abuse to deliver credential phishing attack · Blog · Sublime Security
ID: da8051de-29a2-57ad-a7ec-62bd6a8eaad9
STIX ID: report--da8051de-29a2-57ad-a7ec-62bd6a8eaad9
Feed Name: Sublime Security Blog
Threat Score
This report describes a credential-phishing campaign that abused Zoom Events and Zoom Docs to host a man-in-the-middle phishing page impersonating Microsoft 365 (using a malicious office.regencyoutdor.com link). The attack leverages living-off-the-trusted-sites techniques to appear legitimate and aims to steal user credentials; Sublime's AI detection flagged and prevented the attack while highlighting suspicious sender metadata, vague language, and mismatched hostnames.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
